-const char cgi_rcs[] = "$Id: cgi.c,v 1.42 2002/01/21 00:33:20 jongfoster Exp $";
+const char cgi_rcs[] = "$Id: cgi.c,v 1.62 2002/04/10 19:59:46 jongfoster Exp $";
/*********************************************************************
*
* File : $Source: /cvsroot/ijbswa/current/cgi.c,v $
*
*
* Copyright : Written by and Copyright (C) 2001 the SourceForge
- * IJBSWA team. http://ijbswa.sourceforge.net
+ * Privoxy team. http://www.privoxy.org/
*
* Based on the Internet Junkbuster originally written
* by and Copyright (C) 1997 Anonymous Coders and
*
* Revisions :
* $Log: cgi.c,v $
+ * Revision 1.62 2002/04/10 19:59:46 jongfoster
+ * Fixes to #include in templates:
+ * - Didn't close main file if loading an included template fails.
+ * - I'm paranoid and want to disallow "#include /etc/passwd".
+ *
+ * Revision 1.61 2002/04/10 13:37:48 oes
+ * Made templates modular: template_load now recursive with max depth 1
+ *
+ * Revision 1.60 2002/04/08 20:50:25 swa
+ * fixed JB spelling
+ *
+ * Revision 1.59 2002/04/05 15:51:51 oes
+ * - added send-stylesheet CGI
+ * - bugfix: error-pages now get correct request protocol
+ * - fixed
+ * - kludged CGI descriptions and menu not to break JS syntax
+ *
+ * Revision 1.58 2002/03/29 03:33:13 david__schmidt
+ * Fix Mac OSX compiler warnings
+ *
+ * Revision 1.57 2002/03/26 22:29:54 swa
+ * we have a new homepage!
+ *
+ * Revision 1.56 2002/03/24 17:50:46 jongfoster
+ * Fixing compile error if actions file editor disabled
+ *
+ * Revision 1.55 2002/03/24 16:55:06 oes
+ * Making GIF checkerboard transparent
+ *
+ * Revision 1.54 2002/03/24 16:18:15 jongfoster
+ * Removing old logo
+ *
+ * Revision 1.53 2002/03/24 16:06:00 oes
+ * Correct transparency for checkerboard PNG. Thanks, Magnus!
+ *
+ * Revision 1.52 2002/03/24 15:23:33 jongfoster
+ * Name changes
+ *
+ * Revision 1.51 2002/03/24 13:25:43 swa
+ * name change related issues
+ *
+ * Revision 1.50 2002/03/16 23:54:06 jongfoster
+ * Adding graceful termination feature, to help look for memory leaks.
+ * If you enable this (which, by design, has to be done by hand
+ * editing config.h) and then go to http://i.j.b/die, then the program
+ * will exit cleanly after the *next* request. It should free all the
+ * memory that was used.
+ *
+ * Revision 1.49 2002/03/13 00:27:04 jongfoster
+ * Killing warnings
+ *
+ * Revision 1.48 2002/03/08 17:47:07 jongfoster
+ * Adding comments
+ *
+ * Revision 1.47 2002/03/08 16:41:33 oes
+ * Added GIF images again
+ *
+ * Revision 1.46 2002/03/07 03:48:38 oes
+ * - Changed built-in images from GIF to PNG
+ * (with regard to Unisys patent issue)
+ * - Added a 4x4 pattern PNG which is less intrusive
+ * than the logo but also clearly marks the deleted banners
+ *
+ * Revision 1.45 2002/03/06 22:54:35 jongfoster
+ * Automated function-comment nitpicking.
+ *
+ * Revision 1.44 2002/03/05 22:43:45 david__schmidt
+ * - Better error reporting on OS/2
+ * - Fix double-slash comment (oops)
+ *
+ * Revision 1.43 2002/03/05 21:33:45 david__schmidt
+ * - Re-enable OS/2 building after new parms were added
+ * - Fix false out of memory report when resolving CGI templates when no IP
+ * address is available of failed attempt (a la no such domain)
+ *
* Revision 1.42 2002/01/21 00:33:20 jongfoster
* Replacing strsav() with the safer string_append() or string_join().
* Adding map_block_keep() to save a few bytes in the edit-actions-list HTML.
*
* CGI actions file editor that works and is actually useful.
*
- * Ability to toggle JunkBuster remotely using a CGI call.
+ * Ability to toggle Junkbuster remotely using a CGI call.
*
* You can turn off both the above features in the main configuration
* file, e.g. if you are running a multi-user proxy.
const char cgi_h_rcs[] = CGI_H_VERSION;
+/*
+ * List of CGI functions: name, handler, description
+ * Note: Do NOT use single quotes in the description;
+ * this will break the dynamic "blocked" template!
+ */
static const struct cgi_dispatcher cgi_dispatchers[] = {
{ "",
cgi_default,
- "Junkbuster main page" },
+ "Privoxy main page" },
+#ifdef FEATURE_GRACEFUL_TERMINATION
+ { "die",
+ cgi_die,
+ "<b>Shut down</b> - <em class=\"warning\">Do not deploy this build in a production environment, "
+ "this is a one click Denial Of Service attack!!!</em>" },
+#endif
{ "show-status",
cgi_show_status,
"Show information about the current configuration" },
"Show the source code version numbers" },
{ "show-request",
cgi_show_request,
- "Show the client's request headers." },
+ "Show the request headers." },
{ "show-url-info",
cgi_show_url_info,
"Show which actions apply to a URL and why" },
+#ifdef FEATURE_CGI_EDIT_ACTIONS
{ "toggle",
cgi_toggle,
- "Toggle JunkBuster on or off" },
-#ifdef FEATURE_CGI_EDIT_ACTIONS
+ "Toggle Privoxy on or off" },
{ "edit-actions",
cgi_edit_actions,
"Edit the actions list" },
NULL /* Sends a robots.txt file to tell robots to go away. */ },
{ "send-banner",
cgi_send_banner,
- NULL /* Send the transparent or \"Junkbuster\" gif */ },
+ NULL /* Send a built-in image */ },
+ { "send-stylesheet",
+ cgi_send_stylesheet,
+ NULL /* Send templates/cgi-style.css */ },
{ "t",
- cgi_transparent_gif,
- NULL /* Send a transparent gif (short name) */ },
+ cgi_transparent_image,
+ NULL /* Send a transparent image (short name) */ },
{ NULL, /* NULL Indicates end of list and default page */
cgi_error_404,
NULL /* Unknown CGI page */ }
/*
- * Some images
+ * Bulit-in images for ad replacement
*
- * Hint: You can encode your own GIFs like this:
- * perl -e 'while (read STDIN, $c, 1) { printf("\\%.3o,", unpack("C", $c)); }'
+ * Hint: You can encode your own images like this:
+ * cat your-image | perl -e 'while (read STDIN, $c, 1) { printf("\\%.3o", unpack("C", $c)); }'
*/
-const char image_junkbuster_gif_data[] =
- "GIF89aD\000\013\000\360\000\000\000\000\000\377\377\377!"
- "\371\004\001\000\000\001\000,\000\000\000\000D\000\013\000"
- "\000\002a\214\217\251\313\355\277\000\200G&K\025\316hC\037"
- "\200\234\230Y\2309\235S\230\266\206\372J\253<\3131\253\271"
- "\270\215\342\254\013\203\371\202\264\334P\207\332\020o\266"
- "N\215I\332=\211\312\3513\266:\026AK)\364\370\365aobr\305"
- "\372\003S\275\274k2\354\254z\347?\335\274x\306^9\374\276"
- "\037Q\000\000;";
+#ifdef FEATURE_NO_GIFS
-const int image_junkbuster_gif_length = sizeof(image_junkbuster_gif_data) - 1;
+/*
+ * Checkerboard pattern, as a PNG.
+ */
+const char image_pattern_data[] =
+ "\211\120\116\107\015\012\032\012\000\000\000\015\111\110\104"
+ "\122\000\000\000\004\000\000\000\004\010\002\000\000\000\046"
+ "\223\011\051\000\000\000\006\142\113\107\104\000\310\000\310"
+ "\000\310\052\045\225\037\000\000\000\032\111\104\101\124\170"
+ "\332\143\070\161\342\304\377\377\377\041\044\003\234\165\342"
+ "\304\011\006\234\062\000\125\200\052\251\125\174\360\223\000"
+ "\000\000\000\111\105\116\104\256\102\140\202";
+/*
+ * 1x1 transparant PNG.
+ */
+const char image_blank_data[] =
+ "\211\120\116\107\015\012\032\012\000\000\000\015\111\110\104\122"
+ "\000\000\000\004\000\000\000\004\010\006\000\000\000\251\361\236"
+ "\176\000\000\000\007\164\111\115\105\007\322\003\013\020\073\070"
+ "\013\025\036\203\000\000\000\011\160\110\131\163\000\000\013\022"
+ "\000\000\013\022\001\322\335\176\374\000\000\000\004\147\101\115"
+ "\101\000\000\261\217\013\374\141\005\000\000\000\033\111\104\101"
+ "\124\170\332\143\070\161\342\304\207\377\377\377\347\302\150\006"
+ "\144\016\210\146\040\250\002\000\042\305\065\221\270\027\131\110"
+ "\000\000\000\000\111\105\116\104\256\102\140\202";
+#else
-const char image_blank_gif_data[] =
+/*
+ * Checkerboard pattern, as a GIF.
+ */
+const char image_pattern_data[] =
+ "\107\111\106\070\071\141\004\000\004\000\200\000\000\310\310"
+ "\310\377\377\377\041\376\016\111\040\167\141\163\040\141\040"
+ "\142\141\156\156\145\162\000\041\371\004\001\012\000\001\000"
+ "\054\000\000\000\000\004\000\004\000\000\002\005\104\174\147"
+ "\270\005\000\073";
+
+/*
+ * 1x1 transparant GIF.
+ */
+const char image_blank_data[] =
"GIF89a\001\000\001\000\200\000\000\377\377\377\000\000"
"\000!\371\004\001\000\000\000\000,\000\000\000\000\001"
"\000\001\000\000\002\002D\001\000;";
+#endif
-const int image_blank_gif_length = sizeof(image_blank_gif_data) - 1;
+const size_t image_pattern_length = sizeof(image_pattern_data) - 1;
+const size_t image_blank_length = sizeof(image_blank_data) - 1;
static struct http_response cgi_error_memory_response[1];
-
static struct http_response *dispatch_known_cgi(struct client_state * csp,
const char * path);
static struct map *parse_cgi_parameters(char *argstring);
* Function : dispatch_cgi
*
* Description : Checks if a request URL has either the magical
- * hostname CGI_SITE_1_HOST (usully http://i.j.b/) or
+ * hostname CGI_SITE_1_HOST (usually http://p.p/) or
* matches CGI_SITE_2_HOST CGI_SITE_2_PATH (usually
* http://ijbswa.sourceforge.net/config). If so, it passes
* the (rest of the) path onto dispatch_known_cgi, which
csp->ip_addr_str, csp->http->cmd);
/* Find and start the right CGI function*/
- for (d = cgi_dispatchers; FOREVER; d++)
+ d = cgi_dispatchers;
+ for (;;)
{
if ((d->name == NULL) || (strcmp(path_copy, d->name) == 0))
{
return cgi_error_memory();
}
}
+ d++;
}
}
if (!err) err = map(exports, "hostport", 1, html_encode(csp->http->hostport), 0);
if (!err) err = map(exports, "path", 1, html_encode(csp->http->path), 0);
if (!err) err = map(exports, "error", 1, html_encode_and_free_original(safe_strerror(sys_err)), 0);
+ if (!err) err = map(exports, "protocol", 1, csp->http->ssl ? "https://" : "http://", 1);
if (!err)
{
err = map(exports, "host-ip", 1, html_encode(csp->http->host_ip_addr_str), 0);
if (err)
{
- // Some failures, like "404 no such domain", don't have an IP address.
+ /* Some failures, like "404 no such domain", don't have an IP address. */
err = map(exports, "host-ip", 1, html_encode(csp->http->host), 0);
}
}
{
memset(cgi_error_memory_response, '\0', sizeof(*cgi_error_memory_response));
cgi_error_memory_response->head =
- "HTTP/1.0 500 Internal JunkBuster Proxy Error\r\n"
+ "HTTP/1.0 500 Internal Privoxy Error\r\n"
"Content-Type: text/html\r\n"
"\r\n";
cgi_error_memory_response->body =
"<html>\r\n"
- "<head><title>500 Internal JunkBuster Proxy Error</title></head>\r\n"
+ "<head><title>500 Internal Privoxy Error</title></head>\r\n"
"<body>\r\n"
- "<h1>500 Internal JunkBuster Proxy Error</h1>\r\n"
- "<p>JunkBuster <b>ran out of memory</b> while processing your request.</p>\r\n"
+ "<h1>500 Internal Privoxy Error</h1>\r\n"
+ "<p>Privoxy <b>ran out of memory</b> while processing your request.</p>\r\n"
"<p>Please contact your proxy administrator, or try again later</p>\r\n"
"</body>\r\n"
"</html>\r\n";
* Returns a statically-allocated error response.
*
* Parameters :
- * 1 : csp = Current client state (buffers, headers, etc...)
- * 2 : rsp = http_response data structure for output
- * 3 : template_name = Name of template that could not
+ * 1 : csp = Current client state (buffers, headers, etc...)
+ * 2 : rsp = http_response data structure for output
+ * 3 : template_name = Name of template that could not
* be loaded.
*
* Returns : JB_ERR_OK on success
* parameters.
*
* Parameters :
- * 1 : csp = Current client state (buffers, headers, etc...)
- * 2 : rsp = http_response data structure for output
- * 3 : template_name = Name of template that could not
+ * 1 : csp = Current client state (buffers, headers, etc...)
+ * 2 : rsp = http_response data structure for output
+ * 3 : template_name = Name of template that could not
* be loaded.
*
* Returns : JB_ERR_OK on success
const char *template_name)
{
static const char status[] =
- "500 Internal JunkBuster Proxy Error";
+ "500 Internal Privoxy Error";
static const char body_prefix[] =
"<html>\r\n"
- "<head><title>500 Internal JunkBuster Proxy Error</title></head>\r\n"
+ "<head><title>500 Internal Privoxy Error</title></head>\r\n"
"<body>\r\n"
- "<h1>500 Internal JunkBuster Proxy Error</h1>\r\n"
- "<p>JunkBuster encountered an error while processing your request:</p>\r\n"
+ "<h1>500 Internal Privoxy Error</h1>\r\n"
+ "<p>Privoxy encountered an error while processing your request:</p>\r\n"
"<p><b>Could not load template file <code>";
static const char body_suffix[] =
- "</code></b></p>\r\n"
+ "</code> or one of it's included components.</b></p>\r\n"
"<p>Please contact your proxy administrator.</p>\r\n"
- "<p>If you are the proxy administrator, please put the required file "
+ "<p>If you are the proxy administrator, please put the required file(s)"
"in the <code><i>(confdir)</i>/templates</code> directory. The "
"location of the <code><i>(confdir)</i></code> directory "
- "is specified in the main JunkBuster <code>config</code> "
- "file. (It's typically the JunkBuster install directory"
+ "is specified in the main Privoxy <code>config</code> "
+ "file. (It's typically the Privoxy install directory"
#ifndef _WIN32
- ", or <code>/etc/junkbuster/</code>"
+ ", or <code>/etc/privoxy/</code>"
#endif /* ndef _WIN32 */
").</p>\r\n"
"</body>\r\n"
* (query string) for a CGI were wrong.
*
* Parameters :
- * 1 : csp = Current client state (buffers, headers, etc...)
- * 2 : rsp = http_response data structure for output
+ * 1 : csp = Current client state (buffers, headers, etc...)
+ * 2 : rsp = http_response data structure for output
*
* CGI Parameters : none
*
}
if (!err)
{
- sprintf(buf, "Content-Length: %d", rsp->content_length);
+ sprintf(buf, "Content-Length: %d", (int)rsp->content_length);
err = enlist(rsp->headers, buf);
}
{
/*
* Set Expires to about 10 min into the future so it'll get reloaded
- * occasionally, e.g. if IJB gets upgraded.
+ * occasionally, e.g. if Privoxy gets upgraded.
*/
if (!err)
*
* Description : CGI support function that loads a given HTML
* template from the confdir, ignoring comment
- * lines.
+ * lines and following #include statements up to
+ * a depth of 1.
*
* Parameters :
- * 1 : csp = Current client state (buffers, headers, etc...)
- * 2 : template_ptr = Destination for pointer to loaded
+ * 1 : csp = Current client state (buffers, headers, etc...)
+ * 2 : template_ptr = Destination for pointer to loaded
* template text.
- * 3 : template = name of the HTML template to be used
+ * 3 : template = name of the HTML template to be used
+ * 4 : recursive = Flag set if this function calls itself
+ * following an #include statament
*
* Returns : JB_ERR_OK on success
* JB_ERR_MEMORY on out-of-memory error.
* JB_ERR_FILE if the template file cannot be read
*
*********************************************************************/
-jb_err template_load(struct client_state *csp, char ** template_ptr,
- const char *templatename)
+jb_err template_load(struct client_state *csp, char **template_ptr,
+ const char *templatename, int recursive)
{
+ jb_err err;
char *templates_dir_path;
char *full_path;
char *file_buffer;
+ char *included_module;
+ const char *p;
FILE *fp;
char buf[BUFFER_SIZE];
*template_ptr = NULL;
- /*
- * Open template file or fail
- */
+ /* Validate template name. Paranoia. */
+ for (p = templatename; *p != 0; p++)
+ {
+ if ( ((*p < 'a') || (*p > 'z'))
+ && ((*p < 'A') || (*p > 'Z'))
+ && ((*p < '0') || (*p > '9'))
+ && (*p != '-')
+ && (*p != '.'))
+ {
+ /* Illegal character */
+ return JB_ERR_FILE;
+ }
+ }
+
+ /* Generate full path */
templates_dir_path = make_path(csp->config->confdir, "templates");
if (templates_dir_path == NULL)
return JB_ERR_MEMORY;
}
+ /* Allocate buffer */
+
file_buffer = strdup("");
if (file_buffer == NULL)
{
return JB_ERR_MEMORY;
}
+ /* Open template file */
+
if (NULL == (fp = fopen(full_path, "r")))
{
log_error(LOG_LEVEL_ERROR, "Cannot open template file %s: %E", full_path);
free(full_path);
/*
- * Read the file, ignoring comments.
+ * Read the file, ignoring comments, and honoring #include
+ * statements, unless we're already called recursively.
*
* FIXME: The comment handling could break with lines >BUFFER_SIZE long.
* This is unlikely in practise.
*/
while (fgets(buf, BUFFER_SIZE, fp))
{
+ if (!recursive && !strncmp(buf, "#include ", 9))
+ {
+ if (JB_ERR_OK != (err = template_load(csp, &included_module, chomp(buf + 9), 1)))
+ {
+ free(file_buffer);
+ fclose(fp);
+ return err;
+ }
+
+ if (string_join(&file_buffer, included_module))
+ {
+ fclose(fp);
+ return JB_ERR_MEMORY;
+ }
+
+ continue;
+ }
+
/* skip lines starting with '#' */
- if(*buf == '#')
+ if (*buf == '#')
{
continue;
}
* interpretation.
*
* Parameters :
- * 1 : template_ptr = IN: Template to be filled out.
+ * 1 : template_ptr = IN: Template to be filled out.
* Will be free()d.
* OUT: Filled out template.
* Caller must free().
- * 2 : exports = map with fill in symbol -> name pairs
+ * 2 : exports = map with fill in symbol -> name pairs
*
* Returns : JB_ERR_OK on success
* JB_ERR_MEMORY on out-of-memory error
* this function also frees the passed "exports" map.
*
* Parameters :
- * 1 : csp = Client state
- * 2 : templatename = name of the HTML template to be used
- * 3 : exports = map with fill in symbol -> name pairs.
+ * 1 : csp = Client state
+ * 2 : templatename = name of the HTML template to be used
+ * 3 : exports = map with fill in symbol -> name pairs.
* Will be freed by this function.
*
* Returns : JB_ERR_OK on success
assert(exports);
assert(rsp);
- err = template_load(csp, &rsp->body, templatename);
+ err = template_load(csp, &rsp->body, templatename, 0);
if (err == JB_ERR_FILE)
{
free_map(exports);
string_append(&result, d->name);
string_append(&result, "\">");
string_append(&result, d->description);
- string_append(&result, "</a></li>\n");
+ string_append(&result, "</a></li>");
}
}